ACM Home Page
Please provide us with feedback. Feedback
Supporting structured credentials and sensitive policies through interoperable strategies for automated trust negotiation
Full text PdfPdf (507 KB)
Source ACM Transactions on Information and System Security (TISSEC) archive
Volume 6 ,  Issue 1  (February 2003) table of contents
Pages: 1 - 42  
Year of Publication: 2003
ISSN:1094-9224
Authors
Ting Yu  University of Illinois at Urbana-Champaign, Urbana, IL
Marianne Winslett  University of Illinois at Urbana-Champaign, Urbana, IL
Kent E. Seamons  Brigham Young University, Provo, UT
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 15,   Downloads (12 Months): 136,   Citation Count: 49
Additional Information:

abstract   references   cited by   index terms   review   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/605434.605435
What is a DOI?

ABSTRACT

Business and military partners, companies and their customers, and other closely cooperating parties may have a compelling need to conduct sensitive interactions on line, such as accessing each other's local services and other local resources. Automated trust negotiation is an approach to establishing trust between parties so that such interactions can take place, through the use of access control policies that specify what combinations of digital credentials a stranger must disclose to gain access to a local resource. A party can use many different strategies to negotiate trust, offering tradeoffs between the length of the negotiation, the amount of extraneous information disclosed, and the computational effort expended. To preserve parties' autonomy, each party should ideally be able to choose its negotiation strategy independently, while still being guaranteed that negotiations will succeed whenever possible---that the two parties' strategies will interoperate. In this paper we provide the formal underpinnings for that goal, by formalizing the concepts of negotiation protocols, strategies, and interoperation. We show how to model the information flow of a negotiation for use in analyzing strategy interoperation. We also present two large sets of strategies whose members all interoperate with one another, and show that these sets contain many practical strategies. We develop the theory for black-box propositional credentials as well as credentials with internal structure, and for access control policies whose contents are (respectively are not) sensitive. We also discuss how these results fit into TrustBuilder, our prototype system for trust negotiation.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
Blaze, M., Feigenbaum, J., Ioannidis, J., and Keromytis, A. 1999. The KeyNote Trust Management System Version 2. In Internet Draft RFC 2704.
 
3
4
 
5
Dierks, T. and Allen, C. 1999. The TLS Protocol Version 1.0. IETF.
 
6
Farrell, S. 1998. TLS Extension for Attribute Certificate Based Authorization. IETF.
 
7
Frier, A., Karlton, P., and Kocher, P. 1996. The SSL 3.0 Protocol. Netscape Communications Corp.
 
8
 
9
 
10
Hess, A., Jacobson, J., Mills, H., Wamsley, R., Seamons, K., and Smith, B. 2002. Advanced Client/Server Authetication in TLS. In Network and Distributed System Security Symposium. San Diego, CA.
 
11
IETF 2001. Simple Public Key Infrastructure (SPKI) IETF.
 
12
IETF 2002. Simple Public Key Infrastructure (X.509) (pkix). IETF.
 
13
 
14
 
15
16
 
17
Rescorla, E. 1998. HTTP Over TLS. IETF.
18
 
19
Seamons, K., Winslett, M., and Yu, T. 2001. Limiting the Disclosure of Access Control Policies during Automated Trust Negotiation. In Network and Distributed System Security Symposium. San Diego, CA.
 
20
W3C 2002. Platform for Privacy Preferences (P3P) Specification W3C.
 
21
Winsborough, W., Seamons, K., and Jones, V. 2000. Automated Trust Negotiation. In DARPA Information Survivability Conference and Exposition. Hilton Head Island, SC.
22
23
 
24
Zimmerman, P. 1994. PGP User's Guide. MIT Press.

CITED BY  49


REVIEW

"Caroline Merriam Eastman : Reviewer"

Most interactions on the Internet require at least a minimal level of trust. If you buy something, you want to receive it. If you sell something, you want to get paid for it. If you give out information, you want the release of that information to  more...

Collaborative Colleagues:
Ting Yu: colleagues
Marianne Winslett: colleagues
Kent E. Seamons: colleagues